166
Novell Access Manager 3.1 SP2 Identity Server Guide
n
ov
do
cx (e
n)
16
Ap
ril 20
10
4
Fill in the following fields:
Service Principal Name (SPN):
Specify the value of the servicePrincipalName attribute of the
Identity Server user. For this example configuration, this is
HTTP/amser.provo.novell.com
.
Kerberos Realm:
Specify the name of the Kerberos realm. The default value for this realm is
the domain name of the Active Directory server, entered in all capitals. The value in this field is
case sensitive. For this example configuration, this is
AD.NOVELL.COM
.
JAAS config file for Kerberos:
Verify the default path. This should be the same path to which
you copied the keytab file (see
Step 2
in
“Configuring the Keytab File” on page 163
) and end
with the name of the configuration file,
bcsLogin.conf
.
For Windows, the path needs to contain double slashes, for example:
C:\\Program
Files\\Novell\\jre\\lib\\security
Instructions for creating this file are in
“Creating the bcsLogin Configuration File” on
page 168
.
Kerberos KDC:
Specify the IP address of the Active Directory server.
User Attribute:
Specify the name of the Active Directory attribute that combines the cn of the
user with the DNS domain name to form its value. It is an alternate name for user login. Accept
the default value unless you have set up a different attribute.
5
(Conditional) If you have configured your users to have multiple User Principal Names (UPN)
so they can log in using different names (such as [email protected], [email protected], and
[email protected]), click
New
, specify the suffix (such as @abc.com), then click
OK
.
6
Click
Finish
.
IMPORTANT:
You should create only one Kerberos class. This is caused by a limitation in
the underlying Sun JGSS.
7
On the Local page, click
Methods
>
New.
8
Fill in the following fields:
Display name:
Specify a name that you can use to identify this method.
Class:
Select the class that you created for Kerberos.
Содержание ACCESS MANAGER 3.1 SP2 - README 2010
Страница 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Страница 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...